cbcvebase.
CVE-2024-38553
published 2024-06-19

CVE-2024-38553: In the Linux kernel, the following vulnerability has been resolved: net: fec: remove .ndo_poll_controller to avoid deadlocks There is a deadlock issue found in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: fec: remove .ndo_poll_controller to avoid deadlocks There is a deadlock issue found in sungem driver, please refer to the commit ac0a230f719b ("eth: sungem: remove .ndo_poll_controller to avoid deadlocks"). The root cause of the issue is that netpoll is in atomic context and disable_irq() is called by .ndo_poll_controller interface of sungem driver, however, disable_irq() might sleep. After analyzing the implementation of fec_poll_controller(), the fec driver should have the same issue. Due to the fec driver uses NAPI for TX completions, the .ndo_poll_controller is unnecessary to be implemented in the fec driver, so fec_poll_controller() can be safely removed.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 7f5c6addcdc039c1a7c435857e6284ecac5d97c8 < e2348d8c61d03feece1de4c05f72e6e99f74c650e2348d8c61d03feece1de4c05f72e6e99f74c650
linuxlinux>= 7f5c6addcdc039c1a7c435857e6284ecac5d97c8 < d38625f71950e79e254515c5fc585552dad4b33ed38625f71950e79e254515c5fc585552dad4b33e
linuxlinux>= 7f5c6addcdc039c1a7c435857e6284ecac5d97c8 < accdd6b912c4219b8e056d1f1ad2e85bc66ee243accdd6b912c4219b8e056d1f1ad2e85bc66ee243
linuxlinux>= 7f5c6addcdc039c1a7c435857e6284ecac5d97c8 < 87bcbc9b7e0b43a69d44efa5f32f11e32d08fa6f87bcbc9b7e0b43a69d44efa5f32f11e32d08fa6f
linuxlinux>= 7f5c6addcdc039c1a7c435857e6284ecac5d97c8 < c2e0c58b25a0a0c37ec643255558c5af4450c9f5c2e0c58b25a0a0c37ec643255558c5af4450c9f5
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 5.4.0-204.2245.4.0-204.224
linuxlinux_kernel>= 0 < 5.15.0-130.1405.15.0-130.140
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.4.0-263.2974.4.0-263.297
linuxlinux_kernel>= 0 < 4.15.0-233.2454.15.0-233.245
linuxlinux_kernel>= 3.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.